Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Qnap Helpdesk | 4/12/2019 | 17/6/2026 | This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions. | |
| Modificada | Media (6.5) | 1.3% | — | Otrs FAQOtrs Help DeskOtrs ItsmDebian Linux+1 | 27/11/2019 | 16/6/2026 | An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified | |
| Modificada | Crítica (9.8) | 1.9% | — | Axohelp.c Project Axohelp.cAxodraw2 Project Axodraw2 | 29/10/2019 | 17/6/2026 | In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled. | |
| Modificada | Alta (8.8) | 0.68% | — | Joomsky JS Help Desk | 27/8/2019 | 17/6/2026 | The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Bestwebsoft Zendesk Help Center | 16/8/2019 | 17/6/2026 | The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues. | |
| Modificada | Alta (7.2) | 4.8% | 💥 PoC | Jitbit Helpdesk | 9/8/2019 | 17/6/2026 | Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The… | |
| Modificada | Media (5.5) | 0.41% | — | Docker Credential HelpersFedoraproject FedoraCanonical Ubuntu Linux | 29/7/2019 | 17/6/2026 | docker-credential-helpers before 0.6.3 has a double free in the List functions. | |
| Modificada | Alta (8.8) | 1.5% | — | Helpy.io Helpy | 10/7/2019 | 17/6/2026 | Helpy before 2.2.0 allows agents to edit admins. | |
| Modificada | Crítica (9.8) | 2.4% | — | Fehelper Project Fehelper | 26/6/2019 | 17/6/2026 | FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input. | |
| Modificada | Media (6.1) | 0.88% | — | Helpy.io Helpy | 18/6/2019 | 17/6/2026 | Helpy v2.1.0 has Stored XSS via the Ticket title. | |
| Modificada | Crítica (9.8) | 1.2% | — | Helpsystems Boks | 8/2/2019 | 17/6/2026 | A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation. | |
| Modificada | Media (5.4) | 0.80% | — | Schiocco Support Board - Chat AND Help Desk | 17/10/2018 | 17/6/2026 | In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action. | |
| Modificada | Crítica (9.8) | 2.3% | — | Qnap Helpdesk | 13/8/2018 | 17/6/2026 | Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application. | |
| Modificada | Alta (7.5) | 1.1% | — | Lenovo Help | 13/7/2018 | 17/6/2026 | The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI. | |
| Modificada | Alta (7.5) | 1.0% | — | Helpproject Help | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for HELP, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.1% | — | Lenovo Help | 19/4/2018 | 17/6/2026 | Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information. | |
| Modificada | Alta (7.8) | 0.71% | — | Swisscom Tvmediahelper | 27/3/2018 | 17/6/2026 | Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary… | |
| Modificada | Alta (8.8) | 0.58% | — | Userscape Helpspot | 19/2/2018 | 17/6/2026 | An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account. | |
| Modificada | Media (6.1) | 0.89% | — | Userscape Helpspot | 19/2/2018 | 17/6/2026 | An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the "return" parameter of the "index.php?pg=moderated" endpoint. It executes when the return link is clicked. | |
| Modificada | Media (6.1) | 2.9% | — | Adobe Robohelp | 1/12/2017 | 17/6/2026 | Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2. | |
| Modificada | Media (6.1) | 2.8% | — | Adobe Robohelp | 1/12/2017 | 17/6/2026 | Adobe RoboHelp has a cross-site scripting (XSS) vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Qnap QTS Helpdesk | 6/10/2017 | 17/6/2026 | QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack. | |
| Modificada | Media (5.4) | 0.60% | — | Mirasvit Helpdesk MX | 21/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket. | |
| Modificada | Alta (8) | 1.4% | — | Mirasvit Helpdesk MX | 21/9/2017 | 17/6/2026 | Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files. | |
| Modificada | Alta (8.1) | 7.4% | 💥 Exploit | Helpdeskpro Helpdesk PRO | 20/9/2017 | 17/6/2026 | The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task. |